{"data":{"id":"b32088ff-5aa9-4048-8850-cfbd2249e880","title":"CVE-2026-90970: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from…","summary":"GitLab fixed a vulnerability in its AI Gateway component, CVE-2026-90970, affecting versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Under certain conditions, an authenticated user with Duo Agent Platform access could escape the prompt template sandbox through a specially crafted flow configuration and execute arbitrary commands on the AI Gateway.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90970","publishedAt":"2026-10-02T15:17:12.550Z","cveId":"CVE-2026-90970","cweIds":["CWE-1336"],"cvssScore":"9.9","cvssSeverity":"critical","severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Google"],"affectedVendorsRaw":["GitLab AI Gateway","GitLab Duo Agent Platform"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"GitLab AI Gateway prompt template sandbox escape via crafted flow configuration","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00943,"epssCheckedAt":"2026-10-10T02:56:18.802Z","kevDateAdded":null,"advisoryAliases":["GHSA-5295-vp56-jghq"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:01.573Z","patchAvailable":null,"disclosureDate":"2026-10-02T15:17:12.550Z","capecIds":null,"crossRefCount":1,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]}}